View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 14947 | Bug reports | Security | public | 2019-05-28 16:55 | 2019-05-29 11:14 |
| Reporter | tassoman | Assigned To | DenisChenu | ||
| Priority | none | Severity | minor | ||
| Status | closed | Resolution | duplicate | ||
| Product Version | 3.16.x | ||||
| Fixed in Version | 3.17.x | ||||
| Summary | 14947: Question upload plugin, XSS during title, comment form filling | ||||
| Description | While people is answering a «Question Upload» question type, they might be able to fill «Title» and «Comment» to its files. | ||||
| Steps To Reproduce | Answer a survey having «Question upload» question type. | ||||
| Additional Information | As mitigation, filtering is made after file get submitted to the server and survey managers can disable title and comment fields. | ||||
| Tags | No tags attached. | ||||
| Bug heat | 250 | ||||
| Complete LimeSurvey version number (& build) | 3.16.1+190314 | ||||
| I will donate to the project if issue is resolved | No | ||||
| Browser | Firefox | ||||
| Database type & version | MySql | ||||
| Server OS (if known) | Centos7 | ||||
| Webserver software & version (if known) | Apache | ||||
| PHP Version | 7.2 | ||||
| duplicate of | 14737 | closed | DenisChenu | XSS with file upload |
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2019-05-28 16:55 | tassoman | New Issue | |
| 2019-05-29 11:14 | DenisChenu | Relationship added | duplicate of 14737 |
| 2019-05-29 11:14 | DenisChenu | Assigned To | => DenisChenu |
| 2019-05-29 11:14 | DenisChenu | Status | new => closed |
| 2019-05-29 11:14 | DenisChenu | Resolution | open => duplicate |
| 2019-05-29 11:14 | DenisChenu | Fixed in Version | => 3.17.x |